api_sql_query("INSERT INTO $tbl_courseHome(name,link,image,visibility,admin,address,target) VALUES('".addslashes($name_link)."','".addslashes($link)."','$iconForImportedTools','1','0','$iconForInactiveImportedTools','$target')",__FILE__,__LINE__);
api_sql_query("INSERT INTO $tbl_courseHome(name,link,image,visibility,admin,address,target) VALUES('".Database::escape_string($name_link)."','".Database::escape_string($link)."','$iconForImportedTools','1','0','$iconForInactiveImportedTools','$target')",__FILE__,__LINE__);
$linkAdded=true;
}
@ -123,11 +123,11 @@ else
if ($toolid) // RH: new section
{
$sql = "SELECT name,link,target FROM $tbl_courseHome" .
" WHERE id='" . addslashes($id) . "'";
" WHERE id='" . Database::escape_string($id) . "'";